Skip navigation.

風吹くままに

Drift in the wind.

Posts tagged with "Computer"

STICKY POST

How To Customize Your Blog, Without The Knowledge Of CSS. (Only OPERA Weblog)

,

Don't use this explanation. Opera community changed their original design.
Even if I take time, I will update this topic.

CSSの知識なしにblogをカスタマイズするためのガイドです。(OPERA Weblog 限定)
[GUIDE-1] How to customize your background color and image on both sides.
両サイドの変更方法。
[GUIDE-2] How to decorate your title of an article.
記事のタイトルの飾りつけ。
[For your information] How To Get RGB Color
参考資料、RGBカラーの取得方法。

Privilege Escalation via Panda Security Suite

,

A bug in a kernel driver in Panda’s Internet-Security 2008 and Antivirus+Firewall 2008 can be exploited by attackers to escalate their privileges.

See also:
Panda Internet Security/Antivirus+Firewall 2008 cpoint.sys Kernel Driver Memory Corruption Vulnerability, security advisory from Tobias Klein
Vulnerability detected in the Internet protection level control in Panda Internet Security 2008, security advisory and hotfix download from Panda
Vulnerability detected in the Internet protection level control in Panda Antivirus + Firewall 2008,,security advisory and hotfix download from Panda

Spywareblaster Has Been Upgraded To Version 4

, ,

SpywareBlaster 4.0 Download
http://www.javacoolsoftware.com/sbdownload.html

Caution
JavacoolSoftware, the maker of Spywareblaster, recommend you uninstall the previous version before upgrading to the new one.

Thunderbird 2.0.0.12 Is Now Available

,

Mozilla urged users of Thunderbird to update to its new version(2.0.0.12). In its new version, Mozilla fixed five vulnerabilities. One of which is categorized as critical. This vulnerability allow that attackers can inject malicious code by means of special crafted E-Mails.

See also :
Fixed in Thunderbird 2.0.0.12
Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability

Steer Clear of Vista Service Pack

,

08 Feb. 2008, George Ou posted the blog following message.

I completed the first two installations of Vista SP1 RTM upgrade last night on to my primary desktop computer and my first Vista laptop meant to be my new work computer. The result is a near death experience with my desktop computer, and then a real death experience with the laptop



18 Feb. 2008, heiseSecurity said that we should not install Vista SP1, based on their test result.

Despite the Service Pack, Vista still doesn't correctly handle backup archives which were generated with its predecessor Windows XP. There is no noticeable improvement to notebook battery life either. When tested one notebook only ran for half as long as when running Windows XP. Eight further notebooks didn't run differently in the c't test. There even were some entirely new issues, for example with virus scanners. Norton Antivirus produces error messages, and Bitdefender Antivirus can't be installed any more at all.



20 Feb. 2008, Microsoft has published a list of programs that may "experience a loss of functionality".

20 Feb. 2008, InfoWorld said :

Update has been pulled from Windows Update, but Microsoft has not yet produced a fix for users whose machines either won't boot or reboot constantly... Responding to reports of endlessly rebooting PCs that flooded support newsgroups last week, Microsoft said on Tuesday it had pulled an update designed to prep Windows Vista for Service Pack 1.



Most of us shouldn’t even think about installing SP1 until things are cleared up.

Opera 9.26 is now available.

,

Opera 9.26 closes three security holes.
The latest version is available for Windows, MacOS, Linux, FreeBSD, and Solaris.

From heiseSecurity

The new release remedies three security vulnerabilities, one of which allows attackers to manipulate file input dialogues. When users enter a file name, attackers can cause certain input to be suppressed. As a result, users might upload a file they were not expecting.

Using a MouseEvent – dispatchEvent, a "click" can be sent to an HTML file input element, allowing user input to be selectively captured. This could allow an attacker to construct an arbitrary file path that is subsequently used to upload a file of the attacker's choosing.

Opera has categorised the problem as only moderately dangerous. Nonetheless, the Norwegians were upset when Mozilla informed them of the flaw just one day before making the news public. The flaw has already been remedied in Firefox and SeaMonkey.

Another flaw can be exploited in cross-site scripting attacks, and a third can be used to execute arbitrary scripts via image properties. For more details, see the Opera change log.

Adobe had pushed out the latest version of Adobe Reader

,

Adobe Reader 8.1.2 is now available.
Adobe had released an update to its Adobe Reader that corrects more than two dozen bugs, including several security holes.
One of security holes is actively being exploited to break into Microsoft Windows computers.
And now, attackers have started to exploit its vulnerabilities.

To update:
http://www.adobe.com/products/acrobat/readstep2.html

For Japanese:
http://www.adobe.com/jp/products/acrobat/readstep2.html

ActiveX Vulunerabilities - Facebook, Myspace and Yahoo

,

Web surfers are urged to immediately disable ActiveX controls from IE to protect against a swath of publicly reported—and unpatched—software vulnerabilities.

For more details:
http://www.eweek.com/c/a/Security/ActiveX-Under-Seige-Facebook-MySpace-Image-Uploaders-Vulnerable/
http://www.us-cert.gov/current/index.html#publicly_available_exploit_for_facebook
http://www.kb.cert.org/vuls/id/776931

Sun released another update to its Java.

, ,

This update bring some 370 bug fixes, including a number of security updates.
The update is available for Windows, Linux and Solaris.
To update it, access the link below.
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jre-6u4-b-oth-JPR@CDS-CDS_Developer

Or, you could also visit Sun's Java Homepage and click on the "Do I have Java" link at the top.

Ad-Aware SE Personal(Free) Retired

, ,

Lavasoft stopped shipping updates for Ad-Aware SE Personal(Free) after Dec. 31.
If you want to continue using Ad-Aware, you can upgrade to Ad-Aware 2007 Free. But this version don't suport Windows Operating Systems prior to Windows 2000.

Download HERE

To download it, you can also click on "Download" button in the image below.